Arquivo de vulnerabilidades
O catálogo completo de vulnerabilidades exploradas ativamente (CISA KEV e EUVD/ENISA) que o Radar acompanha — pesquise por CVE, fabricante ou produto.
50 de 1670 vulnerabilidades
CVE: CVE-2021-1870
Fabricante / produto: Apple · iOS, iPadOS, and macOSApple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-6287
Fabricante / produto: SAP · NetWeaverSAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30663
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-3452[fabricante vigiado]
Fabricante / produto: Cisco · Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-3118[fabricante vigiado]
Fabricante / produto: Cisco · IOS XRCisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-8193
Fabricante / produto: Citrix · Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceCitrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-22205
Fabricante / produto: GitLab · Community and Enterprise EditionsGitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-30633
Fabricante / produto: Google · Chromium Indexed DB APIGoogle Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-4428
Fabricante / produto: IBM · Data Risk ManagerIBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-33771[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-31956[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-31207[fabricante vigiado]
Fabricante / produto: Microsoft · Exchange ServerMicrosoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-1040[fabricante vigiado]
Fabricante / produto: Microsoft · Hyper-V RemoteFXMicrosoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-27059[fabricante vigiado]
Fabricante / produto: Microsoft · OfficeMicrosoft Office contains an unspecified vulnerability that allows for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-1367[fabricante vigiado]
Fabricante / produto: Microsoft · Internet ExplorerMicrosoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2020-0601[fabricante vigiado]
Fabricante / produto: Microsoft · WindowsMicrosoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-1147[fabricante vigiado]
Fabricante / produto: Microsoft · .NET Framework, SharePoint, Visual StudioMicrosoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-5544[fabricante vigiado]
Fabricante / produto: VMware · VMware ESXi and Horizon DaaSVMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-2215
Fabricante / produto: Android · Android KernelAndroid Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-0041
Fabricante / produto: Android · Android KernelAndroid Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-0069
Fabricante / produto: MediaTek · Multiple ChipsetsMultiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-9805
Fabricante / produto: Apache · StrutsApache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-42013
Fabricante / produto: Apache · HTTP ServerApache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2021-41773
Fabricante / produto: Apache · HTTP ServerApache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2019-0211
Fabricante / produto: Apache · HTTP ServerApache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2016-4437
Fabricante / produto: Apache · ShiroApache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-17558
Fabricante / produto: Apache · SolrThe Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-17530
Fabricante / produto: Apache · StrutsForced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2017-5638
Fabricante / produto: Apache · StrutsApache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Ransomware conhecido]
CVE: CVE-2018-11776
Fabricante / produto: Apache · StrutsApache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2019-6223
Fabricante / produto: Apple · iOS and macOSApple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30860
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-27930
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30807
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-27950
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-27932
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-9818
Fabricante / produto: Apple · iOS, iPadOS, and watchOSApple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-9819
Fabricante / produto: Apple · iOS, iPadOS, and watchOSApple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30762
Fabricante / produto: Apple · iOSApple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-1782
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-1871
Fabricante / produto: Apple · iOS, iPadOS, and macOSApple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-1879
Fabricante / produto: Apple · iOS, iPadOS, and watchOSApple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30661
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30666
Fabricante / produto: Apple · iOSApple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30713
Fabricante / produto: Apple · macOSApple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30657
Fabricante / produto: Apple · macOSApple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30665
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30761
Fabricante / produto: Apple · iOSApple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2021-30869
Fabricante / produto: Apple · iOS, iPadOS, and macOSApple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
CVE: CVE-2020-9859
Fabricante / produto: Apple · Multiple ProductsApple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.
Ver na fonte ↗Fonte: CISA KEV
Adicionado: 03/11/21
Gravidade: [Exploração ativa confirmada]
